From 7bb90e1922b79d276f866625ecefdcaf5c6e9b08 Mon Sep 17 00:00:00 2001 From: Naram Qashat Date: Thu, 24 Jun 2010 00:34:04 -0400 Subject: The next of a few "CBX OCDing over code style" commits, focusing on src/core/enc_*, plus fixing unintentional broken logic in said modules caused by my first OCD commit. Also added a note to example.conf about enc_sha1 being potentially broken, and slight code style OCD in hashcomp.cpp found by Adam. --- data/example.conf | 15 +++++++++++---- 1 file changed, 11 insertions(+), 4 deletions(-) (limited to 'data') diff --git a/data/example.conf b/data/example.conf index 6e8a2c530..e52cd831a 100644 --- a/data/example.conf +++ b/data/example.conf @@ -95,7 +95,7 @@ uplink */ ipv6 = no - /* + /* * Enable if Services should connect using SSL. * You must have m_ssl loaded for this to work. */ @@ -266,6 +266,13 @@ options * NOTE: enc_old is Anope's previous (broken) MD5 implementation, if your databases * were made using that module, continue to use it and do not use enc_md5. * + * NOTE: enc_sha1 relies on how the OS stores 2+ byte data internally, and is + * potentially broken when moving between 2 different OSes, such as moving from + * Linux to Windows. It is recommended that you use enc_sha256 instead if you want + * to use an SHA-based encryption. If you choose to do so, it is also recommended + * that you first try to get everyone's passwords converted to enc_sha256 before + * switching OSes by placing enc_sha256 at the beginning of the list. + * * Supported: * - enc_none (plain text, no encryption) * - enc_old (old, broken MD5 encryption) @@ -273,8 +280,8 @@ options * - enc_sha1 (SHA1 encryption) * - enc_sha256 (SHA256 encryption with random salts) * - * The first module in this list is the active encryption module. All new passwords are - * encrypted by this module. Old passwords stored in another encryption method are + * The first module in this list is the active encryption module. All new passwords are + * encrypted by this module. Old passwords stored in another encryption method are * automatically re-encrypted by the active encryption module on next identify. * Changing the order of the modules requires the services to restart. */ @@ -598,7 +605,7 @@ options * * nickserv/getpass nickserv/sendpass nickserv/getemail nickserv/suspend * nickserv/resetpass - * + * * nickserv/saset/autoop nickserv/saset/email nickserv/saset/greet * nickserv/saset/icq nickserv/saset/kill nickserv/saset/language nickserv/saset/message * nickserv/saset/private nickserv/saset/secure nickserv/saset/url nickserv/saset/noexpire -- cgit